1. Administrator and contact
The data controller and website administrator is Lemperfieldgroup Pty Ltd, with its business address at Level 7, 123 Eagle Street, Brisbane QLD 4000, Australia. Privacy enquiries may be sent to the non-clickable contact address info@lemperfieldgroup.com or submitted through the contact form.
This Privacy Policy explains how personal information is handled when visitors use the Lemperfieldgroup website, contact the casino hotel, enquire about accommodation, dining, events, accessibility, guest services or responsible casino entertainment, or otherwise communicate with us.
2. Scope and applicable law
We aim to handle personal information consistently with the Australian Privacy Act 1988 and the Australian Privacy Principles. Where the European Union or United Kingdom data protection rules apply because an individual is located in those regions or because our processing falls within their territorial scope, we also apply the principles of the General Data Protection Regulation, including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability.
This policy covers information collected through this static website and direct communications. It does not replace privacy notices that may be provided separately for an on-site casino hotel booking, employment application, event contract, loyalty arrangement, security incident or regulated casino activity.
3. Information we may collect
Depending on the interaction, we may collect identification and contact details such as name, email address, phone number and postal address; enquiry details; accommodation, dining or event preferences; accessibility requirements voluntarily provided by the guest; records of correspondence; technical information such as browser type, device type, approximate location, pages viewed and security logs; and consent or preference records.
For casino hotel services provided at a physical venue, additional information may be required under applicable identification, gaming, security, anti-money laundering, financial crime prevention, age-verification or self-exclusion obligations. Such information is not collected through this general website unless clearly stated at the point of collection.
Please do not submit sensitive information through the general contact form unless it is necessary for an accessibility or safety request. Where sensitive information is provided voluntarily, we process it only for the stated purpose and with an appropriate legal basis.
4. How information is collected
Information may be collected directly when a visitor completes the contact form, writes to us, calls guest services, makes a request at the casino hotel, attends an event, asks for accessibility assistance or communicates with staff. Technical information may be generated automatically by the hosting environment for security, availability and error diagnosis.
The website does not intentionally collect personal information from people under 18 in connection with casino entertainment. Casino access and casino-related services are for adults aged 18 and over. Hotel and general hospitality enquiries involving a minor must be submitted by a parent, guardian or responsible adult.
5. Purposes and legal bases
We may use personal information to answer enquiries; arrange or discuss accommodation, dining, events and guest services; provide accessibility support; maintain website security; prevent fraud or misuse; meet legal and regulatory duties; manage complaints; defend legal claims; improve service quality; and maintain accurate business records.
Under GDPR-style requirements, processing may rely on steps taken at the individual’s request before entering a contract, performance of a contract, compliance with a legal obligation, legitimate interests in operating a secure and effective casino hotel business, consent where required, or protection of vital interests in an emergency. Where legitimate interests are used, we consider the impact on the individual and apply proportionate safeguards.
6. Contact form and communications
The contact form requests only information reasonably needed to understand and respond to an enquiry. Submission is voluntary. Required fields are identified in the form. The website displays a local confirmation message; a separate booking or contractual confirmation is issued only by an authorised representative where applicable.
We do not use the contact details supplied through a service enquiry for unrelated direct marketing unless the person has separately consented or another lawful basis applies. A person may withdraw marketing consent at any time without affecting processing that occurred before withdrawal.
7. Sharing and service providers
Personal information may be shared internally with authorised hotel, casino, events, accessibility, security, legal, finance or guest-services personnel who need it for the stated purpose. We may use carefully selected service providers for website hosting, information technology, communications, professional advice, records management, security or event delivery.
Service providers are expected to act only on documented instructions, protect confidentiality, use appropriate security measures and retain information no longer than necessary. Information may also be disclosed where required by law, court order, regulator, law-enforcement authority or to protect the rights, safety and security of guests, staff or the public.
We do not sell personal information to advertisers or data brokers.
8. International transfers
Some technical or professional service providers may process information outside Australia. Where GDPR transfer rules apply, we use an accepted transfer mechanism where required, such as an adequacy decision, approved contractual clauses or another lawful safeguard, together with supplementary measures where appropriate. Australian disclosures are assessed under the applicable cross-border disclosure requirements.
9. Retention
We retain personal information only for as long as needed for the purpose for which it was collected, including responding to an enquiry, providing a requested service, maintaining security, meeting tax, accounting, gaming, corporate or legal obligations, resolving disputes and enforcing agreements.
General unanswered or completed contact enquiries are normally reviewed for deletion or anonymisation after a reasonable operational period. Contract, incident, regulatory and financial records may require longer retention. When information is no longer required, it is securely deleted, destroyed or de-identified where practicable.
10. Security
We use administrative, physical and technical controls appropriate to the nature of the information and the risks involved. Measures may include access controls, least-privilege permissions, staff confidentiality duties, secure configuration, backups, monitoring, incident procedures and vendor due diligence.
No internet transmission or storage method can be guaranteed completely secure. Visitors should avoid sending unnecessary confidential information through the general enquiry form. Suspected privacy or security incidents may be reported using the contact details in this policy.
11. Individual rights
Subject to applicable law, individuals may request access to personal information, correction of inaccurate information, deletion, restriction of processing, objection to certain processing, portability of information supplied in a structured format, and withdrawal of consent. Individuals may also ask for information about the source, purpose and recipients of their information.
Some rights are limited by legal obligations, regulatory recordkeeping, the rights of other people, security needs or the establishment, exercise or defence of legal claims. We may need to verify identity before acting on a request. We aim to respond within the period required by applicable law and will explain any lawful refusal or extension.
12. Complaints and supervisory authorities
Privacy concerns should first be directed to Lemperfieldgroup so that we can investigate and respond. The complaint should include enough detail to identify the issue without including unnecessary sensitive information.
Individuals may also complain to the Office of the Australian Information Commissioner. Where GDPR or UK GDPR applies, an individual may complain to the competent data protection supervisory authority in the country where they live, work or believe an infringement occurred. Exercising a privacy right does not affect access to ordinary hotel services, although some requested services may be impossible without essential information.
13. Cookies and local technologies
The current website is designed to operate without advertising trackers or behavioural profiling. Details about essential storage, preference technologies and future consent requirements are provided in the Cookie Policy. Non-essential analytics or marketing technologies must not be activated without the consent required by applicable law.
14. Third-party links and venue services
If a future page links to a third-party website, that third party controls its own privacy practices. Visitors should review the relevant notice before submitting information. This website does not provide online casino games, deposits, withdrawals or online betting. Privacy rules for regulated on-site casino operations may also be communicated at the venue.
15. Changes to this policy
We may update this policy to reflect changes in law, technology, website functions or casino hotel operations. The current version is published on this page with its revision date. Material changes will be highlighted where reasonably practicable.